---
id: CVE-2026-80159
title: >-
  Acrobat Reader is affected by an Untrusted Search Path vulnerability that
  could result in privilege escalation
summary: >-
  Acrobat Reader is affected by an Untrusted Search Path vulnerability that
  could result in privilege escalation. An attacker with high privileges could
  leverage this vulnerability to gain elevated access. Exploit depends on
  conditions bey…
severity: medium
cvss: 4
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N'
cwe:
  - CWE-426
vendor: adobe
product: acrobat
affected:
  - 'acrobat >= 24.001.20604, < 24.001.30429'
  - 'acrobat_dc >= 15.008.20082, < 26.002.21901'
  - 'acrobat_reader_dc >= 15.008.20082, < 26.002.21901'
patched:
  - acrobat 24.001.30429
  - acrobat_dc 26.002.21901
  - acrobat_reader_dc 26.002.21901
published: '2026-09-08'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T21:17:47.627'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-80159'
references:
  - url: 'https://helpx.adobe.com/security/products/acrobat/apsb26-141.html'
    label: psirt@adobe.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-10T20:41:03.546777Z'
epss: 0.00195
epssPercentile: 0.08134
ingestedAt: '2026-09-08T21:11:12.369Z'
---

## Overview

Acrobat Reader is affected by an Untrusted Search Path vulnerability that could result in privilege escalation. An attacker with high privileges could leverage this vulnerability to gain elevated access. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

## Affected

- `acrobat >= 24.001.20604, < 24.001.30429`
- `acrobat_dc >= 15.008.20082, < 26.002.21901`
- `acrobat_reader_dc >= 15.008.20082, < 26.002.21901`

## Remediation

Upgrade past the affected range:

- `acrobat 24.001.30429`
- `acrobat_dc 26.002.21901`
- `acrobat_reader_dc 26.002.21901`
